QID 980978
QID 980978: Java (maven) Security Update for org.apache.hadoop:hadoop-main (GHSA-mq8p-h798-xcrp)
The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-mq8p-h798-xcrp for updates pertaining to this vulnerability.
Vendor References
- GHSA-mq8p-h798-xcrp -
github.com/advisories/GHSA-mq8p-h798-xcrp
CVEs related to QID 980978
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mq8p-h798-xcrp | org.apache.hadoop:hadoop-main |
|